MAL-2026-3630

    Dashboard / Malicious Package / MAL-2026-3630

    MAL-2026-3630

    Published: 13 May 2026Last Modified: 23 Jul 2026Aliases: 
    GHSA-mwfv-hv2h-2pgf

    Summary: Malicious code in knot-activesupport-logger (RubyGems)

    Details: Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e) This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters. The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.

    Affected packages

    Package

    Name: knot-activesupport-logger

    Purl: pkg:gem/knot-activesupport-logger

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    7.1.6
    MAL-2026-3630 | CVE-DB